your search that gets the active users with _time and user
| bin _time as Day span=1d
| stats count as visits by user Day
| bin Day as Month span=1mon
| stats dc(user) as userCount sum(visits) as visitCount count(visits) as userDayCount by Month
Now you have one record for each month, with the total unique visitors that month (userCount) and the total number of user-days (userDayCount) and the total number of visits (visitCount). If a particular user visited 50 times across 7 days in a particular month, then he will be counted 1, 7, and 50 times, respectively.
okay thanks for the reply but am asking to create the Active users Vs Total users on splunk.
index=audit action="login attempt" "info=succeeded" | dedup user |rename user as "ActiveUsers"
|stats count(ActiveUsers) AS Active
|join ActiveUsers [ |rest /services/authentication/users splunkserver=local
|fields title roles realname|rename title as ALLuserName |stats count(ALLuserName) AS Total ]